Phone: (011) 7541-421, 3409-301, 3409-335, 6547-293, 3409-310
E-mail: Standards sales: prodaja@iss.rs Education: iss-edukacija@iss.rs Information about standards: infocentar@iss.rs
Stevana Brakusa 2, 11030 Beograd
Main menu

naSRPS EN 17640:2022/A1:2025

Fixed-time cybersecurity evaluation methodology for ICT products

General information

45.99     Feb 27, 2026

50.20    Apr 30, 2026

ISS

I224

European Norm

35.030  

English  

Scope

The scope of EN 17640 remains unchanged, adding the content of composition within:
This document describes a cybersecurity evaluation methodology that can be implemented using pre-defined time and workload
resources, for ICT products. It is intended to be applicable for all three assurance levels defined in the CSA (i.e. basic, substantial and
high).
The methodology is comprised of different evaluation blocks including assessment activities that comply with the evaluation
requirements of the CSA for the mentioned three assurance levels. Where appropriate, it can be applied both to 3rd party evaluation
and self-assessment.

Life cycle

NOW

PROJECT
naSRPS EN 17640:2022/A1:2025
45.99 Dispatch of FV draft to CCMC
Feb 27, 2026

Related project

Adopted from EN 17640:2022/prA1 IDENTICAL

Adopted from EN 17640:2022/prA1 IDENTICAL